Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Security pros savage Tsunami hacker verdict
John Oates, The Register 2005-10-11

Last week Daniel Cuthbert was convicted of breaking the Computer Misuse Act, fined £400, and ordered to pay £600 in costs. As an IT security consultant, it will be a long time before Cuthbert's reputation is restored and it is possible he will never work in the industry again.

Comments Mode:
Security pros savage Tsunami hacker verdict 2005-10-11
Anonymous
Is traversing up three directories always an attempt to take control of the site? It seems to me that it could just as legitimately be an attempt to find out more information (which is consistent with Daniel?s story).

Manipulating the URL is a very common, and as far as I know legitimate, technique. Say that someone passes me a link to a story (which itself does not contain other links). I start removing the right-hand side of the URL until you can get more information. Occasionally this will result in a 403 message, but does that mean it is illegal? Is there just something special about using .. (the Unix method of going up to a higher directory)?

Something does not smell right about this!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11341/32609#32609
He's working for Corsaire now!!! 2006-04-28
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus